Domain 5: Governance, Risk, and Compliance (14%) Flashcards
5.3 Personnel
Least Privilege
Users are only given the lowest level of access needed to perform their
job functions
§ Does everyone in the company need to know employee salary data?
5.3 Personnel
Separation of duties
Requires more than one person to conduct a sensitive task or operation
§ Separation of duties can be implemented by a single user with a user and
admin account
5.3 Personnel
Job rotation
Occurs when users are cycled through various jobs to learn the overall
operations better, reduce their boredom, enhance their skill level, and
most importantly, increase our security
§ Job rotation helps the employee become more well-rounded and learn
new skills
§ Job rotation also helps the organization identify theft, fraud, and abuse of
position
5.4 Risk management Strategies
risk avoidance
A strategy that requires stopping the activity that has risk or
choosing a less risky alternative
5.4 Risk management Strategies
Risk Transfer
A strategy that passes the risk to a third party
5.4 Risk management Strategies
Risk Mitigation
A strategy that seeks to minimize the risk to an acceptable level
5.4 Risk management Strategies
Risk Acceptance
A strategy that seeks to accept the current level of risk and the
costs associated with it if the risk were realized
5.4 Risk Analysis
Residual Risk
The risk remaining after trying to avoid, transfer, or mitigate the
risk
5.4 Risk Analysis
Qualitative risk assessment type
Qualitative analysis uses intuition, experience, and other methods to assign a
relative value to risk
o Experience is critical in qualitative analysis
5.4 Risk Analysis
Quantitative Risk assessment type
Quantitative analysis uses numerical and monetary values to calculate risk
o Quantitative analysis can calculate a direct cost for each risk
o Magnitude of Impact
ALE (annual Loss Expectancy) = SLE (single loss expectancy = AV x EF) x ARO (Annual Rate of Occurence)
Users are only given the lowest level of access needed to perform their
job functions
§ Does everyone in the company need to know employee salary data?
5.3 Personnel
Least Privilege
Requires more than one person to conduct a sensitive task or operation
§ Separation of duties can be implemented by a single user with a user and
admin account
5.3 Personnel
Separation of duties
Occurs when users are cycled through various jobs to learn the overall
operations better, reduce their boredom, enhance their skill level, and
most importantly, increase our security
§ Job rotation helps the employee become more well-rounded and learn
new skills
§ Job rotation also helps the organization identify theft, fraud, and abuse of
position
5.3 Personnel
Job rotation
A strategy that requires stopping the activity that has risk or
choosing a less risky alternative
5.4 Risk management Strategies
risk avoidance
A strategy that passes the risk to a third party
5.4 Risk management Strategies
Risk Transfer